Back to Database
Status published
Medium
CVE-2009-4906
Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP...
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4906
Credits & Attribution
No credits recorded in the NVD database.
References
More from accscripts
View All →CVE-2009-4905
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc...
Medium
6.8
CVE-2008-6294
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass...
High
7.5
CVE-2008-6293
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to...
High
7.5
CVE-2008-6292
Acc Autos 4.0 allows remote attackers to bypass authentication and...
High
7.5
CVE-2008-6291
Acc PHP eMail 1.1 allows remote attackers to bypass authentication...
High
7.5
Affected Vendor
accscripts
View all reports →Affected Software
acc php email
Vulnerable Versions:
1.1
Timeline
Official Publish:
June 25th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.